RE: discovering a service behind a nated network

From: Jason Workman (JasonW_at_meederfinancial.com)
Date: 09/07/04

  • Next message: CHRIS GRABENSTEIN: "RE: e-mail tracing"
    To: linux user <linuxteam@gmail.com>, security-basics@securityfocus.com
    Date: Tue, 7 Sep 2004 16:08:25 -0400 
    
    

    You could try a few different options.

    *Port forward the web service and then ssh to server

    *vpn into the network

    *Utilize a network monitoring tool like Nagios, and have it send you email
    notifications when web server status changes.

    My 2 cents...

    -----Original Message-----
    From: linux user [mailto:linuxteam@gmail.com]
    Sent: Saturday, September 04, 2004 8:55 AM
    To: security-basics@securityfocus.com
    Subject: discovering a service behind a nated network

    Hiya All,
     
    I would like to discover if a service that is behind a NATed network
    is still working, for
    example if a web server is in a private network, Nated behind a
    gateway, how could i from an external network check if the server is
    down/ or there are network problems between the server and the
    gateway? is there a way to use a tool such as traceroute for
    NATed/Firewalled network from an external link?

    The reason i am asking this is because i have been asked that
    question on a job interview, and i did not know what the correct
    answer was, it was related to a web cluster farm then.

    another reason is howto troubleshoot a service that has been port forwarded
    from
    the gateway, the port forwarding works for other services, but this
    specific service is not reachable, and you can not tell whether the NATed
    box
    was down, or the route was down, or what, you could debate that you
    can use ssh to
    the gateway server, but then that is run by a different dept. and you
    have no access to that.

    sorry if my English langauge is a bit rusty

    TIA

    Anst

    ---------------------------------------------------------------------------
    Computer Forensics Training at the InfoSec Institute. All of our class sizes
    are guaranteed to be 12 students or less to facilitate one-on-one
    interaction with one of our expert instructors. Gain the in-demand skills of
    a certified computer examiner, learn to recover trace data left behind by
    fraud, theft, and cybercrime perpetrators. Discover the source of computer
    crime and abuse so that it never happens again.

    http://www.infosecinstitute.com/courses/computer_forensics_training.html
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    Computer Forensics Training at the InfoSec Institute. All of our class sizes
    are guaranteed to be 12 students or less to facilitate one-on-one
    interaction with one of our expert instructors. Gain the in-demand skills of
    a certified computer examiner, learn to recover trace data left behind by
    fraud, theft, and cybercrime perpetrators. Discover the source of computer
    crime and abuse so that it never happens again.

    http://www.infosecinstitute.com/courses/computer_forensics_training.html
    ----------------------------------------------------------------------------


  • Next message: CHRIS GRABENSTEIN: "RE: e-mail tracing"

    Relevant Pages

    • RE: Printing from Win9x clients stops
      ... > and make sure this software does not interfere with SBS Server. ... > clients, please disable it and try again. ... Create a local printer and redirect the port to the network server. ...
      (microsoft.public.windows.server.sbs)
    • Re: Dual NICs, Routing Problem
      ... There can only be one default gateway (unless you are using extra stuff as ... network that is NOT directly attached to one of your interfaces. ... >> Do all the hosts on 192.1.36.0 know that if they want to talk to any host on ... Here, the web server needs to know the IP of eth0 on the DataBase Server, ...
      (alt.os.linux.suse)
    • Re: Using Remote Desktop From an SBS Domain
      ... I should say bypassing my server not the router. ... Right click My Network Places...Properties. ... Internet connection, bypassing my SBS/ISA network all together. ... the port number you connect to from 80 to a port of your ...
      (microsoft.public.windows.server.sbs)
    • Re: Fully parallel Scheme-based language w/ evaluator
      ... Windows Server 2003 and networks in simple - and irreverent - terms. ... If networking really is a big deal, ... Concepts and Terminology in Part I, and The Design and Deployment of Network ...
      (comp.lang.misc)
    • Re: ssh and ids
      ... "Hacker busts into your network and sets ... up an SSH server, RNA picks it up and can let you know that it detected ... But you can't stop with simple "port profiling". ... StealthWatch even takes it a step further ...
      (Focus-IDS)